Google Disrupts NetNut: What It Means If You Rely On Residential Proxies
If you run web scraping, ad verification, AI data collection, price monitoring, or any data pipeline on residential proxies, you have a single point of failure most buyers never check. The story behind the headline isn't really about NetNut. It's about where proxy IPs come from, and what happens to your operation when that source becomes a problem.

Gunnar
Last updated -
Why Hype Proxies

TL;DR
On July 2, 2026, Google's Threat Intelligence Group, the FBI, and Lumen disrupted NetNut, a residential proxy network. Google says that it ran on at least 2 million consumer devices, and that the operation cut the usable pool "by millions."
Google's reason: in a single week of June 2026, it observed 316 distinct threat clusters, cybercriminal and espionage groups, using NetNut nodes to hide their origin. Google reports the devices were enrolled through app SDKs, often without clear consent.
This isn't about one vendor. A pool built from borrowed consumer devices can be degraded overnight, so where your IPs come from is a stability and liability question.
Already relying on NetNut? You'll need to move. The questions to ask any replacement are below, so you don't take on the same risk.
What did Google do to NetNut?
According to Google's Threat Intelligence Group, working with the FBI and Lumen, the operation degraded NetNut's network by cutting its pool of usable devices "by millions". Google's report describes a network built on at least 2 million consumer devices being used as proxy exit nodes. Security researchers track NetNut's network as "Popa".
Google's stated reason: those exit nodes were being used on a large scale for malicious activity. In a single week of June 2026, Google says it observed 316 distinct threat clusters, including both cybercriminal and espionage groups. They routed through suspected NetNut nodes to hide their origin and run password-spray and credential-stuffing attacks.
How the network acquired those devices is the part that still matters when you choose your next provider. Per Google's report, NetNut populated its pool by distributing proxy SDKs bundled into apps and pre-installed on consumer hardware like smart TVs and streaming boxes. The report says owners were enrolled through offers to "share your unused bandwidth", and researchers found the apps often lacked clear consent. If that's right, a large share of those residential IPs came from people who never knowingly agreed to have their home networks used as exit nodes.
Google's response had three parts: it disabled the Google accounts it says NetNut used for command-and-control, shared technical indicators with platform providers and law enforcement, and enabled Google Play Protect to warn users and disable apps that carry NetNut's SDKs.
Law enforcement went further. The FBI and IRS Criminal Investigation seized NetNut's domain, along with hundreds of related domains.
NetNut's parent company, the publicly traded Alarum Technologies (NASDAQ: ALAR), has disputed the "botnet" label for its software, while also saying it takes the matter seriously and will cooperate with law enforcement. For our part, we're reporting what Google published, not making a legal judgment of our own.
This is a pattern, not an exception
NetNut isn't an isolated case, and Google's own title says so: this is its continued disruption of residential proxy networks. In January 2026, Google disrupted IPIDEA, another of the largest residential networks, which quietly powered more than a dozen consumer-facing proxy brands. Days before NetNut, on June 28, 9proxy went offline and did not recover, with users reporting unresponsive support. We covered the IPIDEA takedown when it happened.
Google's reporting emphasises that this industry is interconnected. When one network gets degraded, operators buy capacity from competitors and resell it, which is how a single disrupted backend can be behind a dozen brand names you would never guess are related. So the name on your invoice is not the source of your IPs, and you can be paying one brand while routing through infrastructure that could fail without warning.
What does this mean for your operation?
Two things here still matter after the news fades.
Your supply is only as stable as its source. NetNut didn't lose a handful of IPs. Instead, it lost a large share of its exit nodes almost overnight because the network depended on consumer devices that a coordinated takedown could switch off. If your scraper, your monitoring, or your automation was routing through that pool, your success rate didn't degrade gracefully. It collapsed all at once. When the source of your IPs is a pool of borrowed consumer devices, your pipeline takes on every risk that pool carries: takedowns, sudden capacity loss, and a rush to replace it mid-project.
Sourcing is a liability question, not just a quality question. Most buyers evaluate proxies on speed, price, and success rate. NetNut is the reason to add a fourth: where the IPs come from. Pools built from consumer devices with unclear consent carry legal and reputational exposure that has nothing to do with what you're using them for. You can be doing legitimate work: price monitoring, market research, web scraping, ad verification and AI training data. The infrastructure underneath can still be one investigation away from disruption, or one headline away from becoming your compliance team's problem. When a provider gets taken down, its customers are not the target of the seizure, but they are the ones whose pipelines stop.
The question worth answering is simpler than any benchmark: where do these IPs come from, and can that source disappear?
How does HypeProxies source its proxies?
We source directly on infrastructure we own, not through a layer of borrowed consumer devices. That ownership is the reason a takedown like NetNut's does not reach our supply. Takedowns like this one target networks built on devices enrolled without clear consent and used on a large scale for crime. We're neither of those.
Our IPs don't come from app SDKs or bandwidth-sharing offers. Responsible providers now obtain proper consent for their app-based pools, which is an improvement over what Google described. But consented or not, it's still a pool of borrowed consumer devices, and that pool is exactly the layer that was degraded overnight.
Our IPs are 500K+ static US ISP addresses that sit on real carrier networks, which is why they read as ISP or residential in the IP reputation databases, not datacenter. Run one through any proxy checker, and you get a real ISP ASN, an "ISP" type, and a low fraud score. That is one of the first checks many sites run, the one that blocks datacenter ranges before they even evaluate your traffic.
Like every ISP proxy, ours runs on servers we own inside a datacenter, which is what makes it fast and stable. But that does not make it a datacenter proxy. What a site reads and blocks is the IP, not the datacenter the server runs in, and our IPs sit on real carrier networks, not the cloud and hosting ranges that read as datacenter. The server is in a datacenter. The IP is not.
Spur Intelligence, a firm that tracks proxy and anonymisation networks, found that 42% of the apps on LG's smart-TV platform carry SDKs that quietly turn the device into an exit node. After takedowns like these, any provider that claims ethical sourcing should be able to prove it. We're a proxy company writing about a competitor's takedown, so we mean that about ourselves too. Is there an SDK of ours in some app? Do we resell another network? Is there a get-paid-to app behind our service? For us, the answer to all three is no.
The three sourcing models compare as follows:
Datacenter | Residential (app/SDK) | Owned ISP (ours) | |
|---|---|---|---|
How the IPs are sourced | Spun up on cloud and hosting networks | Consumer home devices, enrolled through app SDKs | Static IPs on real carrier networks, on infrastructure we run |
Consent | Not applicable | Often unclear or missing | No consumer devices in the path |
How it reads in fraud databases | Datacenter, blocked by many sites immediately | Residential or ISP | Residential or ISP |
What a coordinated takedown does | Nothing, but the trust was low to begin with | Can destroy most of the pool overnight, as NetNut demonstrated | No consumer-device layer to switch off |
Datacenter and app-based residential are IPs rented from someone else's network, and you inherit its problems. Owned ISP is IP space on infrastructure we operate ourselves, so you inherit no one else's problems.
Clean sourcing won't control what a customer does with a proxy; nothing will. What it controls is which of three positions you're in when a takedown lands: the network that gets taken down, the reseller that goes down with it, or the standalone operation on its own supply that keeps running. It's what keeps you in the last of the three, and it's why our supply stays online.
Looking for a NetNut alternative? Here's what to check
NetNut's domain has been seized and its network degraded, so if you were routing through it, the question isn't whether to move but how quickly, and to which provider.
If you need stable supply right now, you can switch to cleanly sourced ISP proxies today, starting with a $1 trial. Because they use standard proxy protocols, switching is an endpoint change, not a rebuild. If you'd rather compare first, here's how we compare to NetNut and the other ISP providers.
If you're evaluating rather than switching under pressure, these three checks separate real ISP sourcing from marketing:
Fraud score and IP type. Run the IPs through a checker. Real ISP IPs read as ISP or residential with a low fraud score; a "residential" pool that scores as datacenter is mislabeled.
ASN and reverse DNS. A real carrier IP resolves to an ISP, not to a hosting company like AWS or OVH.
The sourcing model. Ask where the IPs come from: owned infrastructure, a resold pool, or consumer devices enrolled through an app. Only the first is built to survive one.
Our free proxy checker runs the first two for you, no signup, and here's what's worth testing before you trust any ISP proxy. Speed and price are easy to compare. Sourcing is the part that decides whether your pipeline is still running next quarter, and it's the part we built so it doesn't fail when you check it.
Frequently asked questions
Why is NetNut not working?
Its domain was seized on July 2, 2026, and Google disrupted the network, cutting off much of the pool it ran on. If your NetNut proxies are down or have stopped working, that is why. Move to a provider on stable, owned infrastructure.
Is NetNut safe to use now?
No. As of July 2026, it's not safe to use. The FBI and IRS Criminal Investigation seized NetNut's domain on July 2, and Google degraded its network, so it isn't operating as a normal proxy service. The reason to leave isn't the downtime; it's where its IPs came from.
What is a good NetNut alternative?
A good NetNut alternative is one whose IPs come from owned infrastructure rather than a pool of consumer devices. Check how a provider sources its IPs before you commit. That matters more than speed or price.
What is the difference between ISP and residential proxies?
The difference is the source. Residential proxies route through consumer devices, usually enrolled through app SDKs. ISP proxies are static IPs on carrier networks, hosted on infrastructure the provider runs. Both read as residential; ISP is more stable because no consumer device can switch it off.
Can ISP proxies replace residential proxies?
For most use cases, yes, and with more stability. The exceptions are worth knowing: if your targets specifically need large, rotating pools of real residential or mobile IPs, or coverage outside the US, that is a different tool. Either way, the sourcing question still applies: ask where the IPs come from before you buy.
Why did Google disrupt NetNut?
Google says it disrupted NetNut because 316 distinct threat clusters used its exit nodes in a single week of June 2026, and because the devices were enrolled through app SDKs that often lacked clear consent.
Was NetNut a botnet?
Google and independent researchers describe NetNut as a botnet and track it as "Popa." Its parent, Alarum Technologies, disputes that label.
Share on
$1 one-time verification. Unlock your trial today.
Stay in the loop
Subscribe to our newsletter for the latest updates, product news, and more.
No spam. Unsubscribe at anytime.





